Our Privacy Policy

Your trust is important to us. This policy explains how we collect, use, and protect your personal information.

Last Updated: 2025-09-15

1. Introduction

Welcome to ALLIOS. We provide a diverse suite of integrated web applications and platforms designed for various sectors, including financial services (lending and SACCO), healthcare (clinic management), and commerce (business management and Point of Sale). This Privacy Policy outlines our commitment to protecting the privacy of individuals who use our services ("Services").

This document explains what information we collect, why we collect it, how we use and share it, and the controls you have over your information. By using any of our Services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

To provide and improve our wide range of Services, we collect information in several ways. The specific type of information we collect depends on which of our Services you use.

2.1. Information You Provide Directly

This is information you knowingly and actively provide us when using or participating in any of our Services and promotions.

  • Account and Profile Information: When you register for an account, we collect information such as your name, email address, phone number, password, and company name.
  • Financial and Identity Information: For our financial services, we may collect government-issued ID numbers, tax identification numbers, proof of income, employment details, credit history, and bank account information.
  • Protected Health Information (PHI): For our healthcare services, we collect sensitive data including medical history, insurance details, symptoms, diagnoses, treatment plans, and other clinical data. We treat this data with the highest level of confidentiality.
  • Business and Transactional Information: For our business and POS services, we collect data about your business operations, inventory, sales data, customer information, and payment card details (processed in a PCI-DSS compliant manner).
  • Communications: If you contact us directly for support or other inquiries, we may receive additional information about you such as the contents of your message and any attachments you may send.

2.2. Information We Collect Automatically

When you visit our websites or use our applications, we may automatically collect certain information from your device.

  • Log and Usage Data: This includes your Internet Protocol (IP) address, browser type and version, the pages you visit, the time and date of your visit, the time spent on those pages, and other diagnostic data.
  • Device Information: We collect information about the device you use to access our Services, including the hardware model, operating system, unique device identifiers, and mobile network information.
  • Cookies and Tracking Technologies: We use cookies and similar tracking technologies to track activity on our Services and hold certain information. This helps us to improve and analyze our Service.

2.3. Information from Third-Party Sources

We may receive information about you from third-party sources to supplement the information we collect.

  • Credit Bureaus: For our lending services, we may obtain your credit history from credit bureaus to assess risk and determine eligibility.
  • Financial Institutions: We may receive information from banks and other financial partners to facilitate transactions and verify financial status.
  • Publicly Available Sources: We may collect information from public records to verify identity and business details.

3. How We Use Your Information

We use the collected information for various purposes, which are tailored to the specific Services you use. Our primary goal is to provide a secure, efficient, and customized experience.

  • To Provide and Maintain our Services: Delivering the core functionality of our applications, including account management and transaction processing.
  • To Improve and Personalize our Services: Understanding how users interact with our platforms to enhance user experience, develop new features, and provide customized content.
  • For Security and Fraud Prevention: Verifying identity, monitoring for suspicious activity, and protecting the integrity of our platforms and your data.
  • To Communicate with You: Sending transactional notifications, responding to support requests, and providing updates about our Services. We will only send marketing communications with your explicit consent, which you can withdraw at any time.
  • For Legal and Regulatory Compliance: Fulfilling our legal obligations, such as "Know Your Customer" (KYC) requirements, tax reporting, and responding to lawful requests from public authorities.

  • Credit Underwriting and Risk Assessment: Analyzing your financial information and credit history to determine loan eligibility, terms, and interest rates.
  • Loan Disbursement and Management: Facilitating the transfer of funds and managing the entire lifecycle of the loan, including payment schedules and balances.
  • Collections: Managing and communicating regarding overdue payments, and, if necessary, engaging with third-party collection agencies in accordance with applicable laws.
  • Reporting to Credit Bureaus: Reporting loan performance data to credit bureaus, which can impact your credit score.

  • Member Management: Maintaining member records, including share capital, deposits, and contact information.
  • Savings and Loan Processing: Managing member savings accounts, processing loan applications specific to SACCO policies, and disbursing funds.
  • Dividend and Interest Calculation: Calculating and distributing dividends or interest payments to members based on their shares and savings.
  • Regulatory Reporting: Generating reports required by cooperative and financial regulatory bodies.

  • Patient Care and Treatment: Creating and maintaining Electronic Health Records (EHR) to provide, coordinate, and manage healthcare and related services.
  • Appointment Scheduling and Reminders: Managing clinic schedules and sending automated reminders to patients.
  • Billing and Insurance Claims: Processing payments, generating invoices, and submitting claims to insurance providers on behalf of the patient or clinic.
  • Communication with Healthcare Providers: Securely sharing relevant health information with other providers (e.g., specialists, labs, pharmacies) for treatment purposes, only with explicit patient consent or as permitted by law.
  • Public Health Activities: Reporting information to public health authorities as required by law for disease control and other public health purposes.

  • Transaction Processing: Securely processing customer payments via various methods (credit/debit cards, mobile money, etc.). We adhere to Payment Card Industry Data Security Standard (PCI-DSS).
  • Inventory and Sales Management: Tracking stock levels, monitoring sales performance, and generating business analytics reports.
  • Customer Relationship Management (CRM): Managing customer data to support loyalty programs, targeted promotions, and customer service.
  • Employee Management: Managing staff roles, permissions, and performance tracking within the business platform.

4. How We Share Your Information

We do not sell your personal information. We only share your information with third parties in the circumstances described below:

  • Service Providers: We share information with third-party vendors and service providers who perform services on our behalf, such as cloud hosting (e.g., AWS, Azure), payment processing, data analytics, and customer support. These providers are contractually obligated to protect your data and use it only for the services we request.
  • Financial Partners: For lending and SACCO services, we may share information with credit bureaus, partner banks for loan disbursement, and collection agencies (if an account is in default).
  • Healthcare Partners: With your explicit consent, we may share your PHI with other healthcare professionals, laboratories, pharmacies, or insurance companies to facilitate your care and billing.
  • Legal and Law Enforcement: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or a subpoena). We will notify you of such requests unless legally prohibited from doing so.
  • Business Transfers: In the event of a merger, acquisition, bankruptcy, or other sale of all or a portion of our assets, your information may be transferred to the new owner. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.
  • With Your Consent: We may share your information for any other purpose with your explicit consent.

5. Data Security

We take the security of your data very seriously and implement a range of technical, administrative, and physical safeguards to protect it from unauthorized access, use, or disclosure. These measures include:

  • Encryption: We use TLS/SSL encryption for all data transmitted between your device and our servers. Sensitive data, such as financial information and health records, is also encrypted at rest using industry-standard algorithms like AES-256.
  • Access Control: Access to personal data is strictly limited to authorized personnel who have a legitimate business need. We use role-based access controls to ensure employees can only access the data necessary for their job function.
  • Regular Audits and Monitoring: We regularly monitor our systems for vulnerabilities and potential intrusions and conduct periodic security audits and penetration testing.
  • Data Minimization: We only collect and process personal data that is necessary to provide our Services and fulfill our legal obligations.

While we strive to use commercially acceptable means to protect your Personal Information, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security.

6. Data Retention

We retain your personal information for as long as necessary to provide the Services you have requested, or for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our policies. Retention periods vary significantly based on the type of information and the applicable legal requirements:

  • Account Information: Retained for as long as your account is active and for a reasonable period thereafter in case you decide to re-activate the Services.
  • Financial Records: Retained for periods mandated by financial regulations and tax laws, which can be 7 years or longer in some jurisdictions.
  • Health Records: Retained in accordance with medical record retention laws, which vary by jurisdiction but often require retention for many years after the last patient interaction.
  • Transactional Data: Retained for the period necessary for dispute resolution, fraud prevention, and financial auditing.

7. Your Rights and Choices

Depending on your location and the Services you use, you may have the following rights regarding your personal information:

  • Right to Access: You can request a copy of the personal information we hold about you.
  • Right to Rectification: You can request that we correct any inaccurate or incomplete information about you.
  • Right to Erasure (Right to be Forgotten): You can request that we delete your personal information, subject to certain exceptions (e.g., where we are legally required to retain the data).
  • Right to Restrict Processing: You can request that we temporarily or permanently stop processing all or some of your personal data.
  • Right to Data Portability: You can request a copy of your personal data in a machine-readable format to transmit to another service.
  • Right to Object: You can object to us processing your personal data for direct marketing purposes.

To exercise any of these rights, please contact our Data Protection Officer using the contact details provided below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.

8. International Data Transfers

Your information, including personal data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. For transfers of data, we rely on legal mechanisms such as Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.

9. Third-Party Services and Additional Disclosures

Allios integrates with a number of third-party services to deliver functionality such as file storage, email, calendar scheduling, video meetings, and mobile money payments. This section explains what those integrations are, the types of data involved, why we access that data, and how you can control or revoke access.

Google services (Drive, Meet, Calendar, Mail/Gmail, Photos)

When you choose to connect your Google account to Allios (for example to import files from Google Drive, schedule calendar events, join or create Google Meet sessions, send mail using Gmail, or access photos), we may request access to the following data via Google OAuth / API scopes:

  • Basic profile (name, email address, profile picture) used to identify your account and personalize the experience.
  • Gmail (only if you explicitly authorise mail access) used to send or manage email on your behalf when you enable email features.
  • Google Drive & Photos (files, photos, metadata) used to read or store files, attachments, meeting recordings or images you choose to connect or upload to Allios.
  • Google Calendar (events, attendees, reminders) used to create and manage events and reminders for the user when calendar sync is enabled.
  • Google Meet metadata/recordings if you opt to record or store meeting content, recordings or meeting attachments may be stored in Drive/Allios storage as permitted by you.

Why we request this data: to provide the features you enabled (file import/export, scheduling, email sending, meeting creation/recording). We request only the minimum scopes required for each feature and we will not access data you do not explicitly permit.

Google controls & revocation

You can review and revoke Allios access to your Google account at any time via your Google Account → SecurityThird-party apps with account access, or by using the Google account permissions page. If you revoke access some features in Allios that rely on Google will stop working until access is restored.

Google API & OAuth compliance

Allios follows Google's developer policies for apps that access Google user data, including the Google API Services User Data Policy. Where required by Google, we will complete app verification (including a verified privacy policy URL and authorized application branding) and implement any required data handling controls (e.g., limited scopes, data deletion on request, and secure storage). If we request sensitive or restricted scopes (such as Gmail or Drive full access), we will clearly state the purpose at the point of consent.

Mobile money integrations (MTN MoMo, Airtel Money)

Allios may integrate with mobile money providers such as MTN MoMo ( Read More ) and Airtel Money ( More... ) to enable payments, disbursements, or payment collection. When you use mobile money features, we may share and process the following information with the mobile money provider:

  • Phone number and MSISDN required to identify the mobile money account.
  • Transaction details (amount, date/time, transaction ID, reference) to process and reconcile payments.
  • KYC / identity details (where required by the telco or law) e.g., name, national ID, or other identity documents for compliance purposes.
  • Service status and error codes used to report payment success/failure and to provide support.

Why we share this data: to initiate and confirm payments, reconcile transactions in our system, and comply with regulatory and KYC obligations required by the mobile money providers and local law.

Telco privacy & user controls

MTN and Airtel each publish their own privacy notices and terms that explain how they process your data and the rights you have with them. When you initiate a mobile money transaction through Allios, you are also subject to the telco’s terms for that transaction. If you have questions about how the telco processes data, or to exercise rights related to data stored by the telco, please contact MTN or Airtel directly.

Data retention, security, and sharing

We retain data collected via Google and mobile money integrations only for as long as necessary to provide the features you enabled or to comply with legal obligations (for example, financial record retention). Stored recordings, files or transaction logs are protected using industry standard controls (TLS in transit; encryption at rest) and role-based access controls within Allios.

How to review or revoke permissions

  1. Google access: Visit your Google Account → SecurityThird-party apps with account access and remove Allios if required.
  2. Mobile money: Contact your mobile money provider (MTN MoMo or Airtel Money) or follow the provider's in-app or USSD controls to manage linked services. Allios cannot unilaterally remove KYC data stored by a telco; you must contact the telco for telco-side data removal requests.
  3. Allios account data: To request deletion, portability, or correction of data stored by Allios, contact our Data Protection Officer at the email below. We will respond within applicable legal timeframes.

Key third-party policies:

By enabling or using integrations with Google or mobile money providers you consent to the sharing and processing described above. We will update this disclosure as necessary to reflect changes in our integrations or the rules of third-party providers; substantive changes will be posted to this page with an updated Last Updated date.

10. Children's Privacy

Our Services are not intended for use by individuals under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from Children. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. For significant changes, we may also provide a more prominent notice, such as through an email notification. You are advised to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data handling practices, please contact our Data Protection Officer (DPO):

Data Protection Officer
ALLIOS Solutions.
Kampala, Uganda
[email protected]

We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy.

Our Privacy Policy Compliant To

Data Protection Laws

Theme Settings

Choose the color mode for your app.

The perfect color mode for your app.

Choose the font family that fits your app.

Choose the gray shade for your app.

Choose the border radius factor for your app.

Save